CVE-2026-21509
Microsoft Microsoft 365 Apps for Enterprise, Microsoft Office 2016, Microsoft Office 2019
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
- CVSS
- 7.8
- EPSS
- 72.2% 99.4% percentile
- CISA KEV
- Listed
- Published
- 2026.01.27